fix(builtin-deps): Builtin dependencies manifest validation (#17499)
### What does this PR try to resolve? As part of https://github.com/rust-lang/cargo/issues/16960 this PR adds validation checks to reject invalid forms of the manifest including builtin dependencies, such as when they are present in the `build-dependencies` section or combined with other sources. The [RFC](https://rust-lang.github.io/rfcs/3875-build-std-explicit-dependencies.html#) specifies what forms of builtin dependencies are valid. This PR is part of a chain: - https://github.com/rust-lang/cargo/pull/17497 - https://github.com/rust-lang/cargo/pull/17502 - https://github.com/rust-lang/cargo/pull/17498 - https://github.com/rust-lang/cargo/pull/17499 - https://github.com/rust-lang/cargo/pull/17500 ### How to test and review this PR? The PR consists of commits which add a test demonstrating some undesired behaviour and then fixes that in the following commit. Cargo test passes on every commit. 🤖 LLM disclosure: I used Codex to help me understand the codebase and asked it to review my branch before sharing it upstream. I also used it in limited (pre-arranged) ways to generate code, including resolving merge conflicts and updating test assertions. All code was originally written by hand. r? @weihanglo
W
Weihang Lo committed
e2f915c85a9d7999621eae1b2d85d6d2e6bb8822
Committed by GitHub <noreply@github.com>
on 9/23/2026, 3:27:19 PM